1. Overview
Orbit ("Orbit", "we", "us") is a platform run by Startuphouze that connects founders, investors, advisors, and other professionals — through our mobile app and web app at this domain (together, the "Service"). This policy explains what information we collect, why we collect it, who we share it with, and the choices you have.
Orbit is intended for people 18 years of age or older. If you believe a child has created an account, contact us using the details at the bottom of this page and we'll remove it.
2. Information we collect
We collect information in three ways: what you give us, what we generate as you use the Service, and what we receive from third parties you choose to connect.
Account & profile information
Name, email address, and password (we only ever store a one-way cryptographic hash of your password — never the password itself) when you register. Optional profile details you add — phone number, headline, bio, location, company, profile photo, and your role (founder, investor, advisor, professional, service provider, or mentor).
Identity verification
If you choose to verify your professional identity, we ask for supporting documents (e.g. a work ID or LinkedIn profile) reviewed by our team. Founders in India additionally have the option to verify via India's DigiLocker service, which shares your name, date of birth, gender, and a masked identity reference directly from the government system — with your explicit consent through DigiLocker's own consent screen. We never see or store your Aadhaar number itself, only the masked reference DigiLocker provides.
Startup, project & financial information
If you create a startup or project listing: its description, category and stage, funding ask amount and equity offered, pitch deck and pitch video files, and — if you use our investor-snapshot feature — business metrics you enter or that we extract from an uploaded pitch deck (see AI-assisted document parsing below). Investors viewing this information is controlled by the visibility settings you choose.
Communications & content
Posts, comments, likes, messages and files you send through chat, meeting requests, job listings and applications, and event RSVPs — anything you create or send while using the Service.
Calendar integration
If you connect Google Calendar to schedule meetings, we store an encrypted (AES-256) access token so we can create calendar events on your behalf. We only request calendar-write access — not your inbox or other Google data — and you can disconnect it at any time from Settings.
Device & usage information (mobile app)
Our mobile app uses Firebase (Google) for crash reporting, performance monitoring, and push notifications. This can include your device model, operating system version, app version, crash logs, and a push-notification token. We use this to keep the app stable and to notify you of activity relevant to you — not for advertising.
AI-assisted document parsing
If you use the "auto-fill from pitch deck" feature, the text content of your uploaded deck (not the file itself) is sent to OpenAI's API to identify relevant fields (e.g. business model, target customers, revenue streams). This happens only when you choose to use this feature.
3. How we use your information
- To create and secure your account, and verify your identity when requested.
- To operate core features — your feed, search and discovery, connections, messaging, meetings, jobs, and events.
- To send you account, security, and OTP verification emails (via Resend) and SMS (via Twilio) — and, where you've opted in, notifications about activity relevant to you.
- To detect and prevent fraud, abuse, and security incidents, including rate-limiting and monitoring login activity.
- To improve the Service — understanding which features are used and where the app crashes or performs poorly.
- To comply with legal obligations.
5. Data security
- Passwords are never stored in plain text — we store only a bcrypt one-way hash.
- Sensitive tokens (like Google Calendar access tokens) are encrypted at rest with AES-256-GCM.
- All traffic between your device and our servers is encrypted in transit (HTTPS/TLS).
- Account sign-in requires a verified email, and we rate-limit authentication endpoints to slow down automated abuse.
- Access to production systems is restricted to authorized team members.
6. Data retention
We keep your information for as long as your account is active. If you delete your account, we remove your profile, posts, messages, and uploaded files from the Service; some information may be retained for a limited period where required for legal, security, or fraud-prevention purposes (for example, records needed to investigate abuse reports).
7. Your rights & choices
- Access & correction — view and edit your profile information at any time from Settings.
- Deletion — permanently delete your account and associated data from Settings, or by contacting us.
- Notifications — manage which notifications you receive from Settings > Notifications.
- Calendar disconnect — revoke Google Calendar access at any time from Settings > Integrations.
- Depending on where you live, you may have additional rights (such as data portability or objecting to certain processing) under laws like India's DPDP Act or the EU/UK GDPR. Contact us to exercise these.
8. Payments
Orbit does not currently process payments or offer paid subscriptions. If we introduce paid plans in the future, payment will be handled by a PCI-compliant third-party payment processor — Orbit itself will never see or store your full card number. We'll update this policy before any such feature launches.
9. International data transfers
Orbit is operated from India. Several of our service providers (Supabase, Resend, Twilio, OpenAI, Google, Railway, Vercel) process data on servers located outside India, including in the United States. By using the Service, you understand your information may be transferred to and processed in countries other than your own, under contractual safeguards with each provider.
10. Changes to this policy
We may update this policy as the Service changes. If we make material changes, we'll notify you in-app or by email before they take effect. The "last updated" date at the top of this page always reflects the current version.
11. Contact us
Questions about this policy or your data? Email us at support@startuphouze.com.